[CVE-2012-4540] icedtea-web: buffer overflow in IcedTeaScriptableJavaObject::invoke

Related Vulnerabilities: CVE-2012-4540  

Debian Bug report logs - #692608
[CVE-2012-4540] icedtea-web: buffer overflow in IcedTeaScriptableJavaObject::invoke

version graph

Reported by: Luciano Bello <luciano@debian.org>

Date: Wed, 7 Nov 2012 21:03:01 UTC

Severity: grave

Tags: security

Fixed in version 1.3.1-1

Done: Matthias Klose <doko@ubuntu.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, OpenJDK Team <openjdk@lists.launchpad.net>:
Bug#692608; Package icedtea-web. (Wed, 07 Nov 2012 21:03:04 GMT) (full text, mbox, link).


Acknowledgement sent to Luciano Bello <luciano@debian.org>:
New Bug report received and forwarded. Copy sent to OpenJDK Team <openjdk@lists.launchpad.net>. (Wed, 07 Nov 2012 21:03:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Luciano Bello <luciano@debian.org>
To: submit@bugs.debian.org
Subject: [CVE-2012-4540] icedtea-web: buffer overflow in IcedTeaScriptableJavaObject::invoke
Date: Wed, 7 Nov 2012 21:59:04 +0100
Package: icedtea-web
Severity: grave
Tags: security
Justification: user security hole

Hi,
please see : http://seclists.org/oss-sec/2012/q4/237

Cheers,
luciano



Reply sent to Matthias Klose <doko@ubuntu.com>:
You have taken responsibility. (Fri, 09 Nov 2012 10:18:04 GMT) (full text, mbox, link).


Notification sent to Luciano Bello <luciano@debian.org>:
Bug acknowledged by developer. (Fri, 09 Nov 2012 10:18:04 GMT) (full text, mbox, link).


Message #10 received at 692608-done@bugs.debian.org (full text, mbox, reply):

From: Matthias Klose <doko@ubuntu.com>
To: 692608-done@bugs.debian.org
Subject: Fixed in 1.3.1-1
Date: Fri, 09 Nov 2012 11:15:09 +0100
Version: 1.3.1-1



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 11 Dec 2012 07:26:32 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:51:02 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.